To evaluate the effectiveness of current security controls, organizations conduct a GAP analysis. This involves comparing the current state of the organization’s security posture against a desired state, often informed by industry standards like NIST (National Institute for Standardization and Technology) or ISO 27001. These frameworks establish baselines for security configurations that guarantee a level of protection. In the gap analysis, the study identifies areas where security controls are missing, weak, or outdated. For example, a company may discover through GAP analysis that although they have strong technical controls, their employee awareness training is outdated or missing—posing a social engineering risk. This insight allows for targeted improvement and resource allocation.